Practice Approach Work Hybrid Intelligence About Request an audit Start a conversation
Salesforce architecture audit

Find out what's actually wrong with your Salesforce org — before it breaks something.

We audit your permission model, security posture, automation architecture, data model, AI-agent readiness, and delivery pipeline against a fixed 12-domain rubric — every finding scored, evidenced, and ranked by severity. Read-only access or run the export yourself; either way, the free trial preview comes before you pay for anything.

Getting started

Two ways in — read-only, or no access at all

The audit reads configuration metadata only — never your business records. Pick whichever access path your security posture prefers; the report is identical either way.

OPTION A — READ-ONLY USER

Create a least-privilege auditor user

A dedicated user on the Minimum Access profile plus one read-only permission set. No sysadmin, no data access, no write permission on anything.

  • Deploy our pre-built permission set (zip) via Workbench or the sf CLI — exactly 4 permissions: API Enabled, View Setup and Configuration, View All Users, View Roles (read the XML first)
  • Setup → Users → New User, profile: Minimum Access — Salesforce
  • Username: claudio@consultingcloud.io.yourcompany · Email: claudio@consultingcloud.io
  • Check "Generate new password and notify user immediately"
  • Assign the permission set · deactivate the user when we're done
OPTION B — SELF-SERVE EXPORT

Run the export yourself — grant nothing

Our export script runs read-only queries with the Salesforce CLI and writes one JSON file you can inspect before sending. No user created, no access granted — and the script itself is plain bash you can read first.

  • Log in with the Salesforce CLI: sf org login web
  • Download the export toolkit (zip), unzip, read the script, run it
  • Inspect the JSON — config metadata only, zero business records
  • Send us the file (we'll provide an upload link)
THEN

Tell us it's ready

Fill out the form below and we'll take it from there. Optionally add us (username Tiobold, read role) to your Salesforce repo so the audit covers your delivery pipeline too.

  • We confirm within 1 business day
  • You get a free trial preview report first — real findings from your org
  • The full report unlocks the moment you pay — no re-run, no calls required
We will never ask for a System Administrator user, a password, an API token, or a connected-app secret. Option A's "notify user immediately" makes Salesforce email the account-setup link straight to claudio@consultingcloud.io — we never see or transmit a password, and the permission set you create is the complete, inspectable list of what we can read. Option B grants nothing at all.
Pricing

Fixed prices, posted up front

Every audit starts with a free trial preview built from a real run against your org. Pay only if the preview convinces you.

Audit — Core Up to 100 users

Architecture Audit

€1,900 ONE-TIME · EXCL. VAT

The full 12-domain audit: every finding scored, evidenced, and ranked, with a prioritized remediation path.

  • Free trial preview first
  • Blueprint PDF + full evidence appendix
  • Benchmarks vs. orgs we've audited
Audit — Enterprise 500+ users / multi-org

Architecture Audit

from €6,900 ONE-TIME · EXCL. VAT

For orgs where the audit is also an alignment exercise: multiple stakeholders, legacy estates, compliance eyes on the output.

  • Everything in Scale
  • Executive readout for leadership
  • Remediation-sprint scoping included
Recurring After any audit

Drift Monitoring

€490 PER QUARTER · OR €1,600/YEAR PREPAID · EXCL. VAT

We re-run the exact same rubric against your org every quarter and send you what got worse, what got fixed, and what's new — matched finding-by-finding against your last report. Less than one user license per month.

  • Quarterly re-audit + drift diff report
  • Same fingerprinted rubric, so results are comparable
  • Annual prepay ≈ one quarter free · cancel any time
Due diligence M&A / investment

Org Due-Diligence Assessment

from €9,500 PER TARGET · EXCL. VAT

The same evidence-backed audit, packaged for acquirers and investors evaluating a target's Salesforce estate: reproducible, fingerprinted, and defensible in a data room.

  • Fixed scope and turnaround agreed up front
  • Risk quantification for the deal team
  • Run manifest for full reproducibility
Talk to us

All prices in EUR, excluding VAT. Fixed-scope remediation sprints (permission-model cleanup, Workflow Rule / Process Builder retirement, sharing-model redesign) run €2,900–€4,900 fixed per sprint, scoped against your audit's findings — every report ends with a mapped remediation path. A 100-user org typically spends €80k+/year on Salesforce licenses; audits regularly pay for themselves on recovered licenses alone.

What we audit

Twelve domains, one report

Every audit is scored against the same fixed rubric, every time.

ACCESS

Permission model & security

Object/field-level access, sharing rules, MFA, admin sprawl, connected-app exposure.

AUTOMATION

Flows, triggers & deprecated logic

Flow-pattern compliance, plus legacy Workflow Rules and Process Builder still live in production.

CODE & DATA

Apex health & schema hygiene

Test coverage, anti-patterns, field sprawl, record-type and picklist hygiene.

AI READINESS

Agentforce & AI-agent safety

Whether an AI agent could be scoped safely in your org — and what it would inherit today. Learn more →

OPERATIONS

Lead-to-cash & licenses

Quote-to-cash integrity, license utilization, and inactive users still holding paid seats.

GOVERNANCE

Delivery pipeline & drift

Whether your CI/CD pipeline is actually followed — or change is happening around it.

Ready when you are

Finish steps 1 and 2 above, then send us the details below. We'll confirm access and follow up within one business day with a free trial preview.

How will we get your metadata?
Which Salesforce products are in use? (select all that apply)
What's the primary use case?